Anticipated End Date:
2026-10-12
Position Title:
Director I Cybersecurity - Threat Intelligence & Engineering
Job Description:
Director I Cybersecurity - Threat Intelligence & Engineering
Location: This role requires associates to be in-office 3 days per week, fostering collaboration and connectivity, while providing flexibility to support productivity and work-life balance. This approach combines structured office engagement with the autonomy of virtual work, promoting a dynamic and adaptable workplace. Alternate locations may be considered if candidates reside within a commuting distance from an office.
Please note that per our policy on hybrid/virtual work, candidates not within a reasonable commuting distance from the posting location(s) will not be considered for employment, unless an accommodation is granted as required by law.
The Director I Cybersecurity - Threat Intelligence & Engineering is responsible for leading the threat intelligence, detection engineering, threat hunting, and phishing resiliency functions. This leader will translate the external threat landscape and internal telemetry into measurable risk reduction - improving detection coverage, accelerating response, and continuously validating controls.
How you will make an impact:
People & Executive Leadership:
• Build, mentor, and retain a multi-disciplinary team of intel analysts, hunters, detection engineers, red/purple operators, and automation engineers.
• Serve as a trusted advisor to executives on threat landscape, detection posture, and risk-based prioritization.
• Partner with x-functional organizations across privacy, legal, law enforcement, intelligence community, and other intel sharing organizations
Cyber Threat Intelligence (CTI):
• Enhance and direct the enterprise Cyber Threat Intelligence, program, establishing the strategy, requirements, and operating model for threat intelligence and threat hunting.
• Establish and oversee analysis and reporting on adversary tactics, techniques, and procedures, threat actor profiles, and emerging threats.
• Set the strategy and operating model for Threat Intelligence, Threat Hunting, Detection Engineering with AI & Automation.
• Drive zero trust cyber defense - visualization, correlation, and analytics anchored on cyber threat intelligence.
• Manage vendor relationships and external intelligence sharing partnerships
Detection engineering & operations:
• Own and enhance an efficient detection engineering lifecycle and its efficacy from hypothesis, intelligence, deployment, tuning and deprecation.
• Map detection to the industry frameworks like MITRE ATT&CK and real world threat feeds for robust coverage of today's threats and anticipatory of tomorrow's threats based on emerging intelligence.
• Drive purple and red team exercises partnering with the Attack Surface management & red teams.
• Integrate automation and AI capabilities with the AI SOC
Collaboration & Communications:
• Establish team OKRs and outcomes aligned to business risk, security priorities, and industry frameworks (e.g., ATT&CK coverage, MTTD/MTTR improvements, control validation).
• Evaluate and govern adoption of agentic security solutions (AI-driven investigation/response), ensuring safety, auditability, human-in-the-loop controls, and measurable value.
• Communicate complex threats and trends clearly to executive leadership and business stakeholders verbally and through written threat intel briefs.
Minimum Requirements:
Requires an BA/BS degree in Information Technology, Computer Science or related field of study and a minimum of 7 years of IT management experience; or any combination of education and experience, which would provide an equivalent background.
Preferred Skills, Capabilities and Experiences:
• Experience evaluating and operationalizing agentic (AI-driven) security solutions is strongly preferred.
• Seven years in cybersecurity, with at least 5 years leading CTI, detection engineering, or security operations team is preferred.
• Deep familiarity with SOC technologies, threat intelligence, and adversary emulation technologies and practices is strongly preferred.
• Extensive and deep knowledge in industry frameworks like the MITRE ATT&CK framework, NIST, & CIS is preferred.
• Proven track record of managing high performing technical teams, scaling security programs, and driving x-functional cyber debt and risk reduction is strongly preferred.
• Ability to manage across geographically diverse associates and vendor partners strongly preferred.
Job Level:
Director
Workshift:
Job Family:
IFT > IT Tech Strategy
Please be advised that Elevance Health only accepts resumes for compensation from agencies that have a signed agreement with Elevance Health. Any unsolicited resumes, including those submitted to hiring managers, are deemed to be the property of Elevance Health.
NOTE: Workday keeps job postings active through 11:59:59 PM on the day before the listed end date. Example: If the end date is 3/13, the posting will automatically come down on 3/12 at 11:59:59 PM. In other words - the job is posted until 3/13, not through 3/13.